Featured Image for Device Security

Microsoft Account

  • Run Security Checkup
  • Check all 2FA enabled options – Still up-to-date ?
  • Check your personal account details – Your name, address, birthday, …
  • Check access by third party apps and services – Remove unused or unknown connections
  • Check all your devices – Remove unused or unknown devices
  • Enable MFA with Microsoft Authenticator
  • Backup your Microsoft Recovery Code – For example in KeePass2 (its required to restore the access to your account if you entered the password multiple times wrong)
  • Disable Personalized Ads

iCloud Account

  • Enable 2FA
  • Check email and phone numbers
  • Check your personal account details – Your name, address, birthday, …
  • Check account recovery – Remove unknown entries
  • Check accounty security for the MFA – Remove unknown devices
  • Check app specific passwords – Remove all connections if you don’t use it
  • Check family sharing – Remove unknown entries
  • Check all devices – Remove unused or unknown devices
  • Check “Hide my Email” and Forwards – Remove unknown entries
  • Check legacy contacts – Still correct?
  • Disable iCloud Analytics
  • Disable Personalized Ads

Google Account

  • Run Security Checkup
  • Enable 2FA
  • Enable 2FA for activity logs
  • Check all devices – Remove unknown devices
  • Check access by third party apps and services – Remove unused or unknown connections
  • Check backups codes or third party API access – Remove them if you didn’t configured it
  • Disable Personalized Ads

Sunrise Internet Modem / Router

  • Enable Firewall – Don’t allow WAN to LAN access and just allow LAN to WAN with default protocols like HTTP, HTTPS, FTP, SFTP etc.
  • Allow access to admin console only from 192.168.1.0/24
  • Check time server – Default is: time.sunrise.net
  • Check internal DNS – Default is only: 192.168.1.1
  • Change password for the default admin – Default is: The same password like for the WiFi itself (which is anyway crap)
  • Check the routings – Remove unknown IPs in the list
  • Enable Guest WiFi for 2.4GHz & 5GHz
  • Change names for the WiFi – Don’t use the same name WiFi name for the Guest WiFi like for the private one
  • Update passwords for the private and guest WiFi – Keep it different